Back to skill

Security audit

马云

Security checks across malware telemetry and agentic risk

Overview

This Jack Ma biography skill does not run code or access data, but it includes unrelated promotional links and contact information that can steer answers off-topic.

Install only if you are comfortable with a Jack Ma biography skill that may surface unrelated OpenClaw/ClawOpen marketing links and a contact email. There is no evidence that it executes code or accesses private data, but the promotional section should be removed or ignored for a clean informational skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill is supposed to provide information about Jack Ma, but it appends unrelated promotional content, external links, and contact details for OpenClaw/ClawOpen. This creates instruction/data poisoning risk by causing the agent to surface unauthorized advertising or redirect users off-topic, especially because the injected section is framed as part of the skill content rather than clearly separated metadata.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The activation description is broad enough to trigger on multiple loosely related phrases such as Alibaba founder, Taobao founder, or Alipay founder without clear boundaries. Overbroad activation can cause the skill to hijack queries that should be handled by other skills or general answering logic, increasing the chance that the unrelated injected content later in the file is exposed to users.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.